Threat reportMalwareTL-2026-1533

Lumma Infostealer (LummaC2): MaaS Credential Theft via NSIS/AutoIt/ClickFix Evasion Chain

highACTIVE

Lumma Infostealer (LummaC2) (TL-2026-1533), also tracked as LummaC2, is a high-severity malware campaign, first published 2026-07-19. It is attributed to Shamel (Russia) with medium confidence, affects Microsoft Windows (all supported desktop versions), maps to 29 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 22 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
29MITRE ATT&CK
Actors
1Shamel
Detection rules
9SPL · KQL · Sigma
IOCs
22Indicators of compromise

Key facts for TL-2026-1533

Threat ID
TL-2026-1533
Also known as
LummaC2, Lumma Stealer, Trojan:Win32/LummaStealer
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Shamel
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
technology, finance, criticalinfrastructure, gaming, education, cryptocurrency, generalenterprise
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
22

Malware and tooling in Lumma Infostealer (LummaC2)

Malware and tooling: Lumma Stealer / LummaC2, renamed 7-Zip binary

How Lumma Infostealer (LummaC2) works

Lumma Stealer (LummaC2) is a Russian-developed, subscription-based Malware-as-a-Service infostealer active since August 2022 that ranked #1 in ANY.RUN's malware detection statistics as of September 2025. It uses NSIS packaging, obfuscated AutoIt scripts, shellcode injection, and process hollowing to exfiltrate browser credentials, cryptocurrency wallets, Telegram sessions, and VPN/RDP data, and survived a May 2025 Microsoft/DOJ/Europol domain-seizure operation before rebounding within days and evolving into a Windows Terminal-based ClickFix delivery chain disclosed by Microsoft in March 2026.

Lumma Stealer, tracked by the security community as LummaC2, first appeared for sale on Russian-language cybercriminal forums in 2022 and is attributed to a threat actor operating under the alias "Shamel." It is offered as a tiered Malware-as-a-Service subscription (documented pricing from roughly $140/month for a standard build up to $20,000 for a source-code license enabling resale), marketed and supported through Telegram channels with 1,800+ members.

The malware's most recent documented distribution chain (Genians, October 2025) begins with phishing sites disguised as pirated/cracked software. Victims are redirected through multiple intermediary sites to obscure the origin, with the final payload staged on MEGA cloud storage. The downloaded Setup.exe is an NSIS (Nullsoft Scriptable Install System) installer that drops files into %Temp%, opens a decoy document ("Contribute.docx") to distract the victim, and invokes the native Windows utility extrac32.exe to extract a CAB archive disguised as "Make.docx," which actually contains 11 component files including a fragmented, ASCII-obfuscated AutoIt3.exe runtime and a heavily obfuscated compiled AutoIt script full of dummy/junk code. The AutoIt script reassembles the fragmented interpreter, decrypts embedded shellcode, and performs process hollowing/injection into a process that displays as an innocuous file named "Riding.pif" while actually executing the Lumma payload in memory — evading static and process-name-based detections. Before execution, the malware enumerates running processes to detect and evade security products including Sophos, Norton, ESET, and Bitdefender.

Lumma is written in C++ and assembly and targets Chromium-, Mozilla-, and Gecko-based browsers, harvesting session cookies, autofill data, saved passwords, cryptocurrency wallet keys/extensions, Telegram session data, email/FTP/VPN/RDP client credentials, and user documents. Exfiltration occurs over HTTP POST to attacker C2 infrastructure that fronts real backend servers behind proxy layers; C2-delivered configuration files control which browsers/wallets/apps are targeted per victim.

Beyond the phishing/cracked-software vector, Lumma affiliates independently distribute the stealer via malvertising (poisoned search results impersonating legitimate brands), compromised websites injecting malicious JavaScript, GitHub repository social-engineering campaigns (fake tool/cheat repos), and — most prominently — ClickFix / fake-CAPTCHA social engineering, where victims are instructed to press Win+R and paste an attacker-supplied command that downloads and runs the stealer via PowerShell, mshta, or a non-resident EXE/DLL loader.

In May 2025, the FBI and CISA issued joint advisory AA25-141B documenting LummaC2 TTPs and IOCs spanning infections from November 2023 through May 2025, coinciding with a coordinated takedown led by Microsoft's Digital Crimes Unit alongside the US DOJ, Europol, and Japan's Cybercrime Control Center that disrupted approximately 2,300 malicious domains (1,300+ seized or transferred to Microsoft) and targeted the central command-and-control panel infrastructure. LummaC2 operators publicly acknowledged the disruption to their Telegram customer base and stood up replacement domains within 24-48 hours; the government seized those replacement domains as well within days, but the operation ultimately only delayed rather than eliminated the service, and Lumma resumed high-volume operation within weeks.

Most recently, Microsoft Threat Intelligence disclosed (March 5, 2026) a new ClickFix variant observed in campaigns from February 2026 that abandons the traditional Win+R Run-dialog lure — which many EDR products now alert on via process-parentage rules — in favor of instructing victims to open Windows Terminal directly (Win+X, then "I"). This blends malicious command execution into what appears to be a legitimate administrative workflow and defeats detection logic keyed to Run-dialog ancestry. The Windows Terminal session spawns additional PowerShell/Terminal instances that retrieve a ZIP payload alongside a renamed 7-Zip binary, extract further payloads, establish scheduled-task persistence, add Microsoft Defender exclusions for the malware's working directories, exfiltrate host/network reconnaissance data, and finally deploy Lumma Stealer proper. This demonstrates continued rapid TTP evolution specifically engineered to outpace defensive telemetry built around earlier ClickFix indicators.

MITRE ATT&CK techniques used in TL-2026-1533

Collection

T1005 Data from Local System; T1560 Archive Collected Data

Discovery

T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job

Privilege Escalation

T1055 Process Injection

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

stealth

T1218 System Binary Proxy Execution

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Resource Development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Lumma Infostealer (LummaC2)

  • Microsoft — Windows (all supported desktop versions)
    Vulnerable versions: Windows 10; Windows 11

Remediation for Lumma Infostealer (LummaC2)

Immediate actions

  • Block the documented C2 domains and IPs (rhussois[.]su, diadtuky[.]su, todoexy[.]su and associated infrastructure) at DNS/firewall/proxy layer
  • Block or restrict extrac32.exe execution from user-writable temp directories via application control / AppLocker
  • Force browser credential re-authentication and rotate any session cookies/passwords on hosts with confirmed Lumma execution
  • Revoke and rotate cryptocurrency wallet keys and API credentials on any affected endpoint

Workarounds

  • Disable or restrict clipboard-to-Run-dialog and clipboard-to-Terminal paste execution via GPO where feasible
  • Enforce application allowlisting to block AutoIt3.exe execution from non-standard install paths

Longer-term hardening

  • Deploy EDR/behavioral detection tuned to process hollowing and shellcode injection into legitimate-looking processes, not just Run-dialog ancestry
  • Add detection coverage for Windows Terminal (wt.exe)-initiated PowerShell chains, not only cmd.exe/mshta/Run-dialog lineage, to catch the March 2026 ClickFix evolution
  • Monitor for unauthorized Microsoft Defender exclusion additions as a persistence/evasion indicator
  • User awareness training against ClickFix/fake-CAPTCHA social engineering and cracked-software phishing lures
  • Restrict use of NSIS-packaged unsigned installers and cracked-software downloads via web/DNS filtering

Timeline of Lumma Infostealer (LummaC2)

  • Lumma Stealer first appears for sale on Russian-language cybercriminal forums under the alias 'Shamel', offered as a subscription-based Malware-as-a-Service.
  • US government seizes two core LummaC2 command-and-control domains as part of a coordinated Microsoft/DOJ/Europol/Japan Cybercrime Control Center takedown operation.
  • LummaC2 administrators notify their Telegram customer base of three newly stood-up replacement domains for the user panel.
  • Government seizes the three replacement domains; FBI and CISA jointly publish advisory AA25-141B documenting LummaC2 TTPs and IOCs covering infections from November 2023 through May 2025; Microsoft publishes technical breakdown of Lumma delivery techniques.
  • Lumma Stealer operations resume at high volume within weeks of the takedown, rebuilding C2 infrastructure and continuing MaaS sales.
  • Lumma Stealer ranks #1 in ANY.RUN's malware detection statistics as of September 2025, reflecting its status as the most widely detected infostealer in the wild.
  • Genians Threat Intelligence publishes detailed analysis of the NSIS/AutoIt/process-hollowing distribution chain, including confirmed C2 domains, IPs, and file hashes from active campaigns.
  • Microsoft observes a new ClickFix campaign variant abusing Windows Terminal (Win+X, then 'I') instead of the Run dialog to deliver Lumma Stealer, evading EDR rules tuned to Run-dialog process ancestry.
  • Microsoft Threat Intelligence publicly discloses the Windows Terminal-based ClickFix delivery chain, detailing the multi-stage PowerShell/7-Zip payload retrieval, scheduled-task persistence, and Defender-exclusion evasion steps.

Sources cited for Lumma Infostealer (LummaC2)

Detection coverage for TL-2026-1533

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1533 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
22 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-1533

5 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats